• Start IPsec connection via console

    SimpleCloud
    SimpleCloud
    I have an IPSec connection that I would like to start the connection via Console. Which commands do I need for this? I am referring to the second button that can be found next to Activate connection in the SFOS web interface.
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • IPSec Site-to-site VPN breaks every day at around 11AM

    Noni Scho
    Noni Scho
    We have an IPSec Site-to-site VPN that is supposed to connect our site with a couple servers hosted on Microsoft Azure. This worked fine for around 2 years, but since May, every day between 10:30 and 11AM the connection breaks and does not seem to re…
    • 5 months ago
    • UTM Firewall
    • General Discussion
  • site to site vpn

    faycal cod
    faycal cod
    Hi, I need help connecting the headquarters containing device ruijie rg-nbr6210-e and the branch containing device SOPHOS. I have made all the required settings, but there is no connection to find out more. I am at your disposal. Thank you.
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Set source IP for site to site IPSec VPN using 'Tunnel Interface' connection type linking multiple subnets

    JasP
    JasP
    We have multiple site to site VPNs setup with connection type 'Tunnel Interface'. The VPN links connect multiple remote subnets. How does XG pick a source IP because it seems to be random and can change when we re-establish a connection. This causes issues…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • Route based VPN loopback

    Tony Steele
    Tony Steele
    I have a Route based VPN from SOPHOS to SOPHOS. I need to create a loopback to allow a connection back to a server. I am not able to find any information regarding this. In fact from what I can see I am not sure I can even do this with a normal IPSEC…
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • No access to the web admin via VPN-NAT since V20 MR1 update

    schmiegi
    schmiegi
    Hello everyone, We are accessing a customer appliance via IPSEC-S2S VPN. Access is made to an IP that is NATed in the tunnel on the customer side and translated in the IPSec config on the customer side. Nothing special, has always worked. In addition…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS site-to-site SSL VPN static IP address for client

    VGDtech
    VGDtech
    Hello, I have Sophos XG 2300 with firmware 19.5.3 MR-3. I'm trying to set a static IP address for a site-to-site SSL VPN client. Is there any way to achieve this? Whatever I do it keeps getting leased IP address from Global DHCP pool or the VPN…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Received IKE message with invalid SPI (F5D1C2B8) from the remote gateway.

    Deepesh kumar jain
    Deepesh kumar jain
    Received IKE message with invalid SPI (F5D1C2B8) from the remote gateway. Received IKE message with invalid SPI (2AE78327) from the remote gateway. What could be the issue and how to solve it?
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Fortigate 80F v Sophos XG125 IPSec Remote Access

    BrushTech
    BrushTech
    With my license renewal fast approaching and my XG125 rev3 EOL I am at a cross roads as to which vendor I should move forward with. Out of pure frustration, I got my hands on a Fortigate 80F to compare SSLVPN and IPSecVPN remote access throughput. I setup…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Endpoint not able to browse over site to site VPN to backup target

    Mark Tarrant
    Mark Tarrant
    Hello, newbie here with Sophos. I am looking at a (new) client I have inherited who have their servers being backed up locally and then across a site to site VPN to a secondary location. There is one server on a different subnet that has never been…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • IPSec VPN allows traffic to one subnet, but not another.

    ml17
    ml17
    I am trying to establish a Route based site-to-site IPSec VPN connection between two Sophos XG Firewalls (all fully up to date) - I followed this recipe . I have two subnets on the 'HeadOffice' Firewall - 192.168.22.0/24 and 192.168.23.0/24 and I have…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Site-to-Site connected but no traffic over failover GW

    Werner Smit
    Werner Smit
    Good day, On our XG230 [ SFOS 20.0.0 GA-Build222] we have two IPsec site-to-site tunnels on two different GWs. Both connect to the same remote GW but use Different NATed local Subnets to Fortigate Firewall. IPSec policies are the same no change there…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Keep Site-to-site Tunnel Connected?

    Zane Donaldson
    Zane Donaldson
    Hey All, I've created an IPsec tunnel between my Sophos XGS unit and a Meraki with the Sophos unit initiating the connection. Traffic is passing just fine, but the location where the Sophos unit is located has somewhat spotty internet. It appears…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Can`t acces Webadmin or SSH from IPSec VPN (Anymore)

    Maik Martin
    Maik Martin
    Hey everybody, i have a strange Problem. I have Firewall on Main Office and a Firewall in Azure (Both with Firmware SFOS 19.5.3) I have a working VPN and everything seems to be fine. But i cant access the Main Offices Web GUI or SSH CLI from…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Device on BO side of IPSec Site-to-site unable to ping HO side

    Werner van Niekerk
    Werner van Niekerk
    I have a scenario and trying to set something up for the interim. In essence, the requirement is to get an APP server at location A to connect to DB server in location B. The main issue with this is that both locations have the same subnet (E.g 172…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Site-to-site IPsec VPN with Mikrotik and Overlapping network

    Andrea C
    Andrea C
    Hi everyone, I'm having difficulty getting site to site IPsec to work properly with a Mikrotik device. Both LANs use the same class 192.168.99.0/24 and to configure the Sophos (SG115 SFOS 20.0.0 GA-Build222) I followed these instructions: https:/…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS IPSEC site-to-site connection

    admin_idl
    admin_idl
    Hello, We are trying to establish an IPSEC VPN connection between 2 XGs Firewall. There is a Fritzbox behind the firewall at both locations. We have already tested many different settings and policies but keep getting the following error message: …
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Fluctuating WAN IP with Dynamic DNS in Sophos Gateway Firewalls

    Mohammed Minhaz
    Mohammed Minhaz
    I was seeking a solution for an issue encountered with my client’s Sophos Gateway Firewall (Site-to-Site IPsec VPN Setup), which was due to the ISP’s PPPoE Service causing frequent changes in the WAN Interface IP. I’ve learned that Dynamic DNS could…
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Dynamic WAN IP With IPSec Site to Site

    Mohammed Minhaz
    Mohammed Minhaz
    The client has a Sophos XGS107 in the branch office and an XGS2100 in the head office. We have site-to-site IPSec with PSK with HO to 2 BO. Due to the PPPoE WAN IP provided by the ISP, the firewall’s WAN interface IP changes frequently. We face a challenge…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • IPSec site-to-site with login/password authentication

    Alysko
    Alysko
    Hi, I'm trying to set up an IPSec VPN on a Sophos XG to connect as site-to-site to an internet box that serves as a IPSec (IKEv2) VPN server. When configuring a new VPN user, the box only gives username/password and VPN server address. Is it possible…
    • Answered
    • 6 months ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: Policy-Based IPsec with Oracle Cloud Infrastructure(OCI)

    GiuseppeI
    GiuseppeI
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Note: The following KB is an updated version of the Sophos Firewall…
    • 6 months ago
    • Sophos Firewall
    • Recommended Reads
  • XGS IPSec S2S Azure and isolating a shared MAC Mini with SSL VPN Contractor

    WABGOR_DAVE
    WABGOR_DAVE
    Hello all, Network (kinda) and XGS newb is back with another question. I'm pretty sure the answer is going to be a "yes/no and you're just missing this little step to get it done". I've included a summarizing picture. Presently working: We have an…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Possible bug: Issue in site to site VPN ipsec changing WAN interface

    eclipse79
    eclipse79
    Hello, I have an issue with site to site vpn IPSec. I suppose it is a bug. Scenario: You have 1 WAN port (port 2) You have some created site to site VPN IPSEC (initiate the connection type) Follow these steps to reproduce the issue: - Configure…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Multicast Forwarding issues

    Randy Cleveland
    Randy Cleveland
    We have recently set up Multicast forwarding between our main office and a remote location via a site-to-site vpn. The Multicast forwarding is working from the remote location back to the main office, however, the system we need to multicast in the…
    • 7 months ago
    • Sophos Firewall
    • Discussions
  • Multicast Traffic Forwarding over IPSec vpn

    Randy Cleveland
    Randy Cleveland
    We are trying to forward multicast traffic for 239.1.1.2 between our Main Site to one of our remote sites via a Site-to-Site IPSec VPN connection. I have following the instructions here: https://support.sophos.com/support/s/article/KB-000038580?language…
    • Answered
    • 7 months ago
    • Sophos Firewall
    • Discussions
<>